ISO 27001 · clause 5.2

The policy on one page

What has to be in it
Four
Fits what your company actually doesNot a template with another company's purpose in it
Holds the security objectivesOr the framework you use to set them
Commits you to applicable requirementsLegal ones and contractual ones
Commits you to continual improvementOf the management system, not just the controls
Where it has to live
Three
Written down
Communicated inside the company
Available outside, where it makes sense
Keep it short

Technical rules belong in the topic-specific policies underneath. A policy nobody reads fails the communication test.